Summary & highlights
astro.config.mjs Supply Chain Attack via Blockchain Dead-Drop C2 (PolinRider / js.jadesnow). Fake GitHub 'EQVita' Homebrew Repo Delivers SmartLoader and Lumma Stealer to the Retro Gaming / PlayStation Vita Modding Community. Airoha Bluetooth SoC Authentication Bypass & RACE Protocol Abuse (CVE-2025-20700/20701/20702) Enables Microphone Eavesdropping and Connection Hijacking on Beats Studio Buds and 28+ Headphone Models.
Highlights
- TL-2026-0846 — astro.config.mjs Supply Chain Attack via Blockchain Dead-Drop C2 (PolinRider / js.jadesnow)
- TL-2026-0849 — Fake GitHub 'EQVita' Homebrew Repo Delivers SmartLoader and Lumma Stealer to the Retro Gaming / PlayStation Vita Modding Community
- TL-2026-0850 — Airoha Bluetooth SoC Authentication Bypass & RACE Protocol Abuse (CVE-2025-20700/20701/20702) Enables Microphone Eavesdropping and Connection Hijacking on Beats Studio Buds and 28+ Headphone Models
- TL-2026-0851 — Roblox Developer Group Takeovers via Malicious 'robase' Python Package and Discord Job-Offer Social Engineering
- TL-2026-0852 — International Law Enforcement Disrupts SocGholish (js.fakeupdates) Access-Broker Infrastructure Linked to Evil Corp
Theme of the day
Active exploitation of various vulnerabilities enabled evasion, credential harvesting, and malware delivery. Threat actors targeted multiple sectors with phishing, supply-chain attacks, and unauthenticated code execution.
- financially-motivated
- infostealer
- masquerading
- social-engineering
- credential-theft
Threats published
16 threat lines in the 2026-06-18 debrief, most severe first. Each links to its full profile.
- F5 Out-of-Band Patches for Critical NGINX HTTP/3 Use-After-Free and Proxy/gRPC Heap Overflow (CVE-2026-42530, CVE-2026-42055) plus NGINX Gateway Fabric Config Injection (CVE-2026-11311, CVE-2026-50107)CRITICAL
- usbliter8 — Unpatchable BootROM USB DMA Exploit on Apple A12/A12X/A12Z/A13 and S4/S5 Chips Bypassing Secure BootCRITICAL
- astro.config.mjs Supply Chain Attack via Blockchain Dead-Drop C2 (PolinRider / js.jadesnow)HIGH
- Fake GitHub 'EQVita' Homebrew Repo Delivers SmartLoader and Lumma Stealer to the Retro Gaming / PlayStation Vita Modding CommunityHIGH
- Airoha Bluetooth SoC Authentication Bypass & RACE Protocol Abuse (CVE-2025-20700/20701/20702) Enables Microphone Eavesdropping and Connection Hijacking on Beats Studio Buds and 28+ Headphone ModelsHIGH
- Roblox Developer Group Takeovers via Malicious 'robase' Python Package and Discord Job-Offer Social EngineeringHIGH
- International Law Enforcement Disrupts SocGholish (js.fakeupdates) Access-Broker Infrastructure Linked to Evil CorpHIGH
- Klue OAuth Supply-Chain Breach Enables 'Icarus' Salesforce CRM Data-Theft Extortion CampaignHIGH
- CryptoBandits Windows Crypto-Clipper Campaign: USB LNK Worm + Tor Hidden-Service C2 (Trojan:Win32/CryptoBandits)HIGH
- Multiple Vulnerabilities in Firefox 152 Enable Remote Code Execution and Sandbox Escape (MFSA 2026-57)HIGH
- Anthropic claude.ai Shared-Chat Feature Abused in ClickFix Malvertising Campaign Delivering MacSync macOS InfostealerHIGH
- OXLOADER Malware Loader Delivering CASTLESTEALER .NET Infostealer via Node.js MalvertisingHIGH
- Popa Botnet — Android TV Box Residential-Proxy Malware (Vo1d/Mzmess Plugin) Linked to NetNut / Alarum TechnologiesHIGH
- Versatile Werewolf (HeartlessSoul): Fondue.exe LOLBin Abuse via APPWIZ.cpl Side-Loading Delivers Sliver Implant and SoullessRATHIGH
- AutoJack: Single-Page RCE Against Hosts Running AI Agents (AutoGen Studio MCP WebSocket Confused-Deputy Chain)HIGH
- Operation Endgame Dismantles SocGholish (FakeUpdates) Initial-Access Malware Network — 106 Servers and 101 Domains Seized (TA569 / Evil Corp)HIGH
Techniques observed
138 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1005
- T1008
- T1011.001
- T1016
- T1020
- T1021
- T1027
- T1027.013
- T1033
- T1036
- T1036.005
- T1041
- T1046
- T1047
- T1048
- T1048.002
- T1052.001
- T1053
- T1053.005
- T1055
- T1056
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.007
- T1068
- T1070
- T1071
- T1071.001
- T1074
- T1078
- T1082
- T1083
- T1090
- T1090.003
- T1091
- T1095
- T1098
- T1102
- T1105
- T1106
- T1112
- T1113
- T1114
- T1115
- T1120
- T1123
- T1132
- T1140
- T1185
- T1189
- T1190
- T1195
- T1199
- T1200
- T1203
- T1204
- T1204.001
- T1204.002
- T1211
- T1212
- T1213
- T1217
- T1218
- T1406
- T1407
- T1437
- T1482
- T1486
- T1490
- T1495
- T1496
- T1497
- T1497.001
- T1499
- T1499.004
- T1505
- T1518
- T1526
- T1528
- T1530
- T1531
- T1539
- T1542
- T1542.001
- T1542.002
- T1542.003
- T1543
- T1544
- T1546
- T1547
- T1548.002
- T1550
- T1552
- T1552.001
- T1553
- T1553.006
- T1555
- T1555.003
- T1557
- T1559
- T1560
- T1562
- T1562.001
- T1564
- T1564.001
- T1565.001
- T1566
- T1566.002
- T1567
- T1573
- T1573.001
- T1574
- T1574.002
- T1580
- T1583
- T1583.008
- T1584
- T1585
- T1586
- T1587
- T1588
- T1592
- T1592.002
- T1595
- T1601.002
- T1608
- T1608.001
- T1614
- T1614.001
- T1620
- T1637
- T1650
- T1655
- T1656
- T1657
Threat actors
7 named threat actors across the reports.
- PolinRider
- Water Kurita (SmartLoader operators) / Storm-2477 (Lumma developer)
- TA569 (Mustard Tempest)
- Icarus
- Vo1d / Mzmess operators (Popa proxy layer linked to NetNut)
- Versatile Werewolf
- TA569 (SocGholish operator)
Nation-state attribution
- North Korea
- Russia
Threat categories
- SUPPLY_CHAIN
- MALWARE
- VULNERABILITY
Severity breakdown
- critical2
- high14
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 133
- network 98
- file 81
- infrastructure 20
- tool 17
- malware 16
- entity 13
- package 8
- technique 5